{"id":"CVE-2026-80943","title":"kernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (CVE-2026-80943)","summary":"A flaw was found in the Linux kernel's rtlwifi driver. This vulnerability occurs when the `rtl92du_tx_fill_desc()` function uses a Quality of Service (QoS) Traffic Identifier (TID) value greater than 8 as an index into an array that only h…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Linux","affected":["Linux >= 8321424134a400a5e3eb39f9acca6bc6946ff447 < 6e327f14e1c43e175bf530f9165b2cadff308553","Linux >= 8321424134a400a5e3eb39f9acca6bc6946ff447 < 0c0b374e12d52af23ca741728db31091677cf9dc","Linux >= 8321424134a400a5e3eb39f9acca6bc6946ff447 < 42785f7e8d31540e6172bbcf08a7cc3cae1086f8","Linux >= 8321424134a400a5e3eb39f9acca6bc6946ff447 < ed4f05d9f2f42fd866f55108db8123eefcc5fb33","Linux 6.11"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T15:54:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80943.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80943.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80943"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532256"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80943"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80943"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80943.mbox"},{"url":"https://git.kernel.org/stable/c/6e327f14e1c43e175bf530f9165b2cadff308553"},{"url":"https://git.kernel.org/stable/c/0c0b374e12d52af23ca741728db31091677cf9dc"},{"url":"https://git.kernel.org/stable/c/42785f7e8d31540e6172bbcf08a7cc3cae1086f8"},{"url":"https://git.kernel.org/stable/c/ed4f05d9f2f42fd866f55108db8123eefcc5fb33"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00247,"epssPercentile":0.16259,"scores":{"vendor":5.5,"cna":7.6},"ingestedAt":"2026-09-14T15:23:07.476Z","slug":"CVE-2026-80943","body":"## Overview\n\nA flaw was found in the Linux kernel's rtlwifi driver. This vulnerability occurs when the `rtl92du_tx_fill_desc()` function uses a Quality of Service (QoS) Traffic Identifier (TID) value greater than 8 as an index into an array that only has 9 allocated entries. A remote attacker could potentially exploit this out-of-bounds array access, leading to memory corruption and potentially a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80943.json)\n\n**kernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202745,"id":"CVE-2026-80943","ts":1789403715411,"field":"cvss","old":"7.6","new":"5.5"},{"seq":202744,"id":"CVE-2026-80943","ts":1789403715411,"field":"severity","old":"high","new":"medium"},{"seq":183822,"id":"CVE-2026-80943","ts":1789356677549,"field":"cvss","old":"7.6","new":"5.9"},{"seq":183821,"id":"CVE-2026-80943","ts":1789356677549,"field":"severity","old":"high","new":"medium"},{"seq":153124,"id":"CVE-2026-80943","ts":1789285349125,"field":"cvss","old":null,"new":"7.6"},{"seq":153123,"id":"CVE-2026-80943","ts":1789285349125,"field":"severity","old":"none","new":"high"},{"seq":147570,"id":"CVE-2026-80943","ts":1789270211427,"field":"cvss","old":null,"new":"5.9"},{"seq":147569,"id":"CVE-2026-80943","ts":1789270211427,"field":"severity","old":"none","new":"medium"},{"seq":109328,"id":"CVE-2026-80943","ts":1789183731444,"field":"cvss","old":null,"new":"5.9"},{"seq":109327,"id":"CVE-2026-80943","ts":1789183731444,"field":"severity","old":"none","new":"medium"}]}